Bizarre crates.io phishing campaign

Observable: crates[.]ws
Observable Type: Domain

Details:

Rust maintainer phishing email sending users to a bogus Crates website.

Interestingly it looks like the .ws domain redirects to .io unless you provide it direct parameters. Unclear the intention though.

Full URI in the email:

https://crates[.]ws/settings/profile?action=verify&e=SOMENUMBER

1 Like

You’ll never guess who owns these:

crates.ws.              273     IN      A       104.21.95.240
crates.ws.              273     IN      A       172.67.149.164

Certificate and DNS both brand spanking new.

URLScan has a fun subdomain:

github-oauth.crates[.]ws